News Analysis • 4 min read
Navigating the Conflict Between AI Trade Secrets and DPDP Access Rights
An analysis for General Counsels on the emerging policy conflict between proprietary AI training logic and Data Principal access rights under the DPDP Act 2023, and how to structure vendor contracts for defensibility.
Last updated:
What happened
A recent Nasscom community report highlights an emerging policy conflict between AI data training practices, trade secret protections, and privacy rights enforced under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The shift in legal philosophy from property rights to dignity rights grants individuals extensive control over their personal data. However, the report notes that debates regarding the independence and enforcement powers of the Data Protection Board of India are causing friction. This friction suggests potential delays in achieving the harmonisation goals set by MeitY, especially concerning complex data use cases like artificial intelligence.
Does the DPDP Act apply here?
Under Section 3 of the DPDP Act, the law applies to the processing of digital personal data within the territory of India. It also covers processing outside India if such processing is in connection with offering goods or services to Data Principals in India. If your enterprise utilises AI models that ingest or generate personal data falling within this territorial scope, the Act applies directly. Section 3 also provides an exemption for personal data made publicly available by the Data Principal, which is highly relevant for AI web scraping, though relying on this requires careful privileged review to verify the original data source.
Legal implications under DPDP
The core of this regulatory tension lies in the absence of a specific trade secret carve-out within the DPDP Act. Under Section 4, consent is the primary basis for processing, except where Section 7 legitimate uses apply. When an individual exercises their right to access or right to information under the Act, companies face a severe conflict of laws. Complying with the access request might force a business to disclose proprietary AI logic or training data, effectively waiving trade secret protections. Conversely, refusing the request to protect intellectual property risks non-compliance penalties, leaving legal leaders to navigate this dilemma without a clear statutory safe harbour.
Could this happen to you
For a General Counsel evaluating enterprise AI vendors, this conflict represents immediate litigation and regulatory risk. If a Data Principal submits a complex access request, your organisation is accountable as the Data Fiduciary. If your AI vendor refuses to disclose how the data was processed due to proprietary trade secrets, the DPBI will hold your enterprise liable for the compliance failure. In the event of an associated data breach, the Rules, 2025 mandate intimation to affected Data Principals without delay and a detailed report to the DPBI within 72 hours. Defensibility requires proving you can compel vendor cooperation, otherwise you risk penalties of up to 250 crore rupees for failing fiduciary obligations.
What companies should do in the next 30 days
1. Legal heads must review and renegotiate vendor contracts to include stringent indemnity clauses and explicit limitation of liability allocations concerning DPDP access request failures.
2. Outside counsel spend should be directed toward creating a defensible legal stance on what constitutes publicly available data under Section 3 for any AI tools currently in deployment.
3. Work with technical teams to map where personal data intersects with proprietary algorithms to establish a clear extraction workflow that protects trade secrets while fulfilling regulatory mandates.
What to watch
Legal departments should closely monitor the DPBI as it establishes its regulatory cadence and finalises operational guidance. There is an expectation that MeitY may need to adopt a middle-path approach or operational carve-outs in future iterations of the notified rules to balance dignity rights with intellectual property protections. 271 days remain until the 13 May 2027 hard deadline, meaning General Counsels must prioritise regulator engagement readiness and structural compliance before enforcement begins. Assess your legal exposure and vendor contract readiness with a free scan at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to data scraped for AI training?
Yes, the Act applies to processing digital personal data within India. However, Section 3 provides an exemption if the personal data was made publicly available by the Data Principal to whom it relates.
How does the lack of a trade secret carve-out impact our AI vendors?
The DPDP Act does not explicitly exempt trade secrets from Data Principal access requests. Fiduciaries face a conflict between disclosing proprietary logic to satisfy access rights or facing penalties for non-compliance.
What liability do we hold if an AI vendor refuses a data access request?
As the Data Fiduciary, your organisation remains liable for fulfilling Data Principal rights. Failure to comply can result in penalties up to 250 crore rupees, making stringent indemnity clauses in vendor contracts essential.
What are the breach notification timelines if our AI vendor exposes personal data?
Under the DPDP Rules 2025, you must provide intimation to affected Data Principals without delay. Additionally, a detailed report must be submitted to the Data Protection Board of India within 72 hours.
What is the primary lawful basis for processing personal data in AI models?
Under the DPDP Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Fiduciaries must ensure verifiable records of this lawful basis are maintained.
ComplyDP